CVE-2026-15047: s2Member < 260805 - Contributor+ Stored XSS via Shortcode
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15047?
CVE-2026-15047 has a risk rating of 43, indicating a substantial security vulnerability.
How do I fix CVE-2026-15047?
To fix CVE-2026-15047, you should update the s2Member plugin to version 260805 or later.
What types of attacks does CVE-2026-15047 facilitate?
CVE-2026-15047 enables stored cross-site scripting (XSS) attacks by allowing contributor-level users to inject JavaScript.
Who is affected by CVE-2026-15047?
Any WordPress site using the s2Member plugin version before 260805 is vulnerable to CVE-2026-15047.
What are the consequences of exploiting CVE-2026-15047?
Exploiting CVE-2026-15047 can result in unauthorized JavaScript execution, potentially compromising user data and site integrity.